CVE-2026-85541
DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.
- Published Sep 4, 2026
- CVSS 4.8 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)